Privacy Policy
Last updated: March 2026
1. Introduction
Nolorem ("we", "our", or "us") is operated by Bonalogic. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our platform at nolorem.io.
We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
The data controller responsible for your personal data is:
- Company: Bonalogic
- Platform: Nolorem (nolorem.io)
- Privacy contact: info@nolorem.io
3. Data We Collect
We collect the following categories of personal data:
Account Information
Name, email address, and organization details provided during signup and account management.
Usage Data
Pages visited, features used, interaction patterns, and timestamps to improve our service and understand usage.
Content Data
Blog posts, social media content, research queries, outlines, and other materials you create or generate through the platform.
Payment Data
Billing information processed securely through Stripe, including your email and subscription details. We do not store credit card numbers on our servers.
Technical Data
IP address, browser type, device information, operating system, and referring URLs collected automatically when you access the platform.
4. How We Use Your Data
Your data is used for the following purposes:
- Service delivery: Providing and maintaining the Nolorem platform, including content creation, scheduling, and publishing features.
- Billing: Processing payments, managing subscriptions, and issuing invoices through Stripe.
- Transactional emails: Sending account confirmations, billing receipts, publishing notifications, and trial expiration warnings via Resend.
- AI content generation: Processing your prompts, topics, and outlines through AI providers (Anthropic, OpenAI) to generate blog posts and social media content.
- Image generation: Processing image prompts through Fal.ai to create AI-generated images for your content.
- Research: Using Perplexity and Tavily to gather research data for your content topics.
- Analytics improvement: Analyzing anonymized usage patterns to improve features and user experience.
5. Legal Basis
We process your personal data on the following legal bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)): Processing necessary to deliver the services you subscribed to, including content generation, publishing, and account management.
- Legitimate interests (Art. 6(1)(f)): Service improvement through anonymized analytics, fraud prevention, and platform security.
- Consent (Art. 6(1)(a)): Non-essential cookies and any future marketing communications. You may withdraw consent at any time.
6. Data Sharing & Sub-processors
We share your data with third-party sub-processors only as necessary to deliver the Service. We do not sell your personal data. Our sub-processors include:
- Supabase — Authentication and database
- Stripe — Payment processing
- Anthropic — AI text generation (primary)
- OpenAI — AI text generation (fallback)
- Fal.ai — AI image generation
- bundle.social — Social media scheduling & publishing
- Apify — Content discovery scraping
- DataForSEO — Keyword research
- Perplexity — AI research (primary)
- Tavily — AI research (fallback)
- Resend — Transactional email
For full details on each sub-processor, including data categories and locations, see our Data Processing Agreement.
7. International Transfers
Some of our sub-processors are based in the United States. Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) as approved by the European Commission.
8. Data Retention
We keep the personal data below only for as long as it serves the purpose it was collected for. The periods are:
- Request logs and IP addresses: Kept for 90 days, then deleted. This lets us detect a shared or abused API key and investigate recent suspicious traffic.
- Administrative access records: Kept for 24 months. After that period the identifying details in the record are replaced so it can no longer be traced to the person or workspace involved, while the fact that access took place is kept for accountability.
- AI generation and audit records: Kept for 12 months, then deleted. These are operational records used to diagnose issues and measure cost, not a copy of the content you created.
- In-app notifications: Kept for 6 months after you have read them, then deleted. A notification you have not read yet is kept until you read it, however old it is.
- Invitations: The invited person's email address is removed 30 days after an invitation is accepted, expires or is withdrawn. A pending invitation keeps the address until it reaches one of those outcomes. What stays afterwards is a record that an invitation existed, without the address.
- Marketing signups: Kept for 24 months, or removed earlier if you ask us to.
9. Records Kept After Erasure
When you exercise your right to erasure, your personal data is deleted or made anonymous. Two kinds of record continue to exist afterwards, and neither one identifies you.
- Records of administrative access: If a Nolorem administrator ever accessed your workspace, for example while helping with a support request, the record that this happened is kept. The details that identified you or the administrator are replaced so the record can no longer be traced to either of you. We keep it on the basis of accountability, so we can show, if ever asked, that access to a workspace took place and was recorded, without that record naming anyone.
- A record that you made this request: We keep a record that a data subject request was received and when it was answered, so we can show that we met the legal deadline. This record does not include the personal data you asked us to erase.
10. Anonymous Feedback
Feedback you leave on our support articles, for example rating whether an article helped or leaving a comment, is not linked to your account or to any other personal data. Because we never connect it to who you are, we cannot trace it back to you or recognise it as yours to remove on request. It falls outside the scope of an erasure request for that reason: there is no personal data in it to erase.
11. Data Held By Our Payment Processor
Your name, billing address, payment details and invoices are held by Stripe, our payment processor, under Stripe's own legal obligation to retain financial records for tax purposes. Nolorem does not hold this data directly and cannot delete it from Stripe's systems when you delete your account.
Your personal data file describes what Stripe holds about you rather than including it, because it exists in Stripe's systems under Stripe's own privacy notice. You can obtain your invoices and billing details from Stripe through your billing portal, or by asking us.
12. Your Rights
Under GDPR and applicable privacy laws, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you. You can download this yourself at any time as a personal data file, without needing to contact us.
- Right to rectification: Request correction of inaccurate or incomplete personal data.
- Right to erasure: Request deletion of your personal data ("right to be forgotten").
- Right to data portability: Request your data in a structured, commonly used, machine-readable format. Your personal data file already meets this; an organization administrator can additionally request a full export of everything held for the workspace.
- Right to restrict processing: Request that we limit how we use your data.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent.
- Right to lodge a complaint: File a complaint with your local data protection supervisory authority.
Access, erasure and portability are self-service: you run them yourself from Settings, Data Export, or from the account settings page. Restriction, objection and withdrawal of consent have no screen in the platform, because each one is a judgement about a specific processing activity rather than a switch; ask us by email and we apply them by hand, within the same 30 days.
To exercise any of these rights, contact us at info@nolorem.io. We will respond within 30 days.
13. Cookies
We use essential cookies required for the platform to function, including authentication and session management. By default, we do not set non-essential tracking cookies.
If you have accepted non-essential cookies via our cookie consent banner, we may use analytics cookies to understand usage patterns. You can change your cookie preferences at any time using the "Cookie Preferences" link in the site footer.
14. Children
Nolorem is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child under 16, please contact us at info@nolorem.io and we will promptly delete it.
15. Changes
We may update this Privacy Policy from time to time. For material changes, we will notify you via email at the address associated with your account. The "Last updated" date at the top of this page indicates when the policy was last revised.
16. Contact
For privacy-related inquiries, data subject requests, or concerns about how we handle your personal data, contact us at:
- Email: info@nolorem.io
- Company: Bonalogic